summaryrefslogtreecommitdiffstats
path: root/pkgs/development/libraries/libxcrypt/default.nix
blob: 056a2cbd946a93c0de8efed229ffead82c2ec5f1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
{
  lib,
  stdenv,
  fetchurl,
  perl,
  # Update the enabled crypt scheme ids in passthru when the enabled hashes change
  enableHashes ? "strong",
  nixosTests,
  runCommand,
  python3,
}:

stdenv.mkDerivation (finalAttrs: {
  pname = "libxcrypt";
  version = "4.5.2";

  src = fetchurl {
    url = "https://github.com/besser82/libxcrypt/releases/download/v${finalAttrs.version}/libxcrypt-${finalAttrs.version}.tar.xz";
    hash = "sha256-cVE6McAaQovM1TZ6Mv2V8RXW2sUPtbYMd51ceUKuwHE=";
  };

  patches = [
    # https://github.com/besser82/libxcrypt/pull/221
    ./fix-symver-on-non-elf.patch
  ];

  # this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion
  # necessary for FreeBSD code path in configure
  postPatch = ''
    substituteInPlace ./build-aux/m4-autogen/config.guess --replace-fail /usr/bin/uname uname
  '';

  outputs = [
    "out"
    "man"
  ];

  configureFlags = [
    "--enable-hashes=${enableHashes}"
    "--enable-obsolete-api=glibc"
    "--disable-failure-tokens"
    # required for musl, android, march=native
    "--disable-werror"
  ]
  ++ lib.optional stdenv.hostPlatform.isCygwin "--disable-symvers";

  makeFlags =
    let
      lld17Plus = stdenv.cc.bintools.isLLVM && lib.versionAtLeast stdenv.cc.bintools.version "17";
    in
    [ ]
    # fixes: can't build x86_64-w64-mingw32 shared library unless -no-undefined is specified
    ++ lib.optionals stdenv.hostPlatform.isPE [ "LDFLAGS+=-no-undefined" ]

    # lld 17 sets `--no-undefined-version` by default and `libxcrypt`'s
    # version script unconditionally lists legacy compatibility symbols, even
    # when not exported: https://github.com/besser82/libxcrypt/issues/181
    ++ lib.optionals lld17Plus [ "LDFLAGS+=-Wl,--undefined-version" ];

  nativeBuildInputs = [
    perl
  ];

  strictDeps = true;

  enableParallelBuilding = true;

  doCheck = true;

  passthru = {
    tests = {
      inherit (nixosTests) login shadow;

      passthruMatches = runCommand "libxcrypt-test-passthru-matches" { } ''
        ${python3.interpreter} "${./check_passthru_matches.py}" ${
          lib.escapeShellArgs (
            [
              finalAttrs.src
              enableHashes
              "--"
            ]
            ++ finalAttrs.passthru.enabledCryptSchemeIds
          )
        }
        touch "$out"
      '';
    };
    enabledCryptSchemeIds = [
      # https://github.com/besser82/libxcrypt/blob/v4.5.0/lib/hashes.conf
      "y" # yescrypt
      "gy" # gost_yescrypt
      "sm3y" # sm3_yescrypt
      "7" # scrypt
      "2b" # bcrypt
      "2y" # bcrypt_y
      "2a" # bcrypt_a
      "6" # sha512crypt
    ];
  };

  __structuredAttrs = true;

  meta = {
    changelog = "https://github.com/besser82/libxcrypt/blob/v${finalAttrs.version}/NEWS";
    description = "Extended crypt library for descrypt, md5crypt, bcrypt, and others";
    homepage = "https://github.com/besser82/libxcrypt/";
    platforms = lib.platforms.all;
    maintainers = with lib.maintainers; [
      dottedmag
      hexa
    ];
    license = lib.licenses.lgpl21Plus;
  };
})